We Hacked An AWS Account. Again.

We Hacked An AWS Account. Again.

Source: YouTube · John Hammond · published Aug 23, 2023 · 16:56

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

The video demonstrates how attackers can escalate from GitHub repository access to full AWS admin compromise by exploiting misconfigurations in Kubernetes and Crossplane 10:01.

Key Takeaways:
• Crossplane allows creating AWS resources from Kubernetes manifests, typically using AWS admin roles by default 1:07
• Attackers can steal AWS tokens by creating a malicious pod with the same service account as the Crossplane AWS provider 6:13
• Cloud security vulnerabilities are becoming more prevalent than traditional web vulnerabilities as companies rapidly adopt cloud infrastructure without proper security measures 13:33
• Small initial access in CI/CD pipelines can lead to cascading compromise across multiple systems 1:47

This demonstration highlights the critical security gaps in modern cloud environments where misconfigurations can lead to complete infrastructure compromise.

Sources:

  • 1:07 Explanation of Crossplane functionality and default AWS admin roles
  • 1:47 Discussion about Crossplane security risks and permission boundaries
  • 6:13 Demonstration of stealing AWS tokens through Kubernetes service account exploitation
  • 10:01 Summary of the full attack chain from GitHub to AWS admin
  • 13:33 Discussion about cloud security vulnerabilities and their prevalence

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

so this should give me AWS credentials to access as this rule that's so crazy full compromise AWS game we've currently gone from Just Right access to Apple request in GitHub to kubernetes admin to AWS admin alrighty hey welcome back Carlos Ignacio all my great friends from halborn look this is it this is the finale this is all the time that we've spent together leading up to this moment chatting about cicd devops infrastructures code digging into terraform digging into kubernetes and AWS uh and now I think we've got a one last sweet demo in Show and Tell for us but uh hey thanks so much for all of you doing this incredible stuff I know you're doing all this incredible work at halborn for security Audits and assessments seeing these horror stories and Nightmare scenarios in the real world u…